# How to get libheic

**URL:** https://meta.discourse.org/t/how-to-get-libheic/412496
**Category:** Self-hosting
**Created:** [September 15, 2026, 4:31pm UTC](https://meta.discourse.org/t/how-to-get-libheic/412496 "2026-09-15T16:31:07Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [September 15, 2026, 4:55pm UTC](https://meta.discourse.org/t/how-to-get-libheic/412496/2 "2026-09-15T16:55:20Z")

</div>

I wouldn’t recommend manually overriding the base image - that’ll mean using an image which we haven’t tested for production use. Plus there is the risk of forgetting to unpin, as you said.

I’ll look at whether we can bump the image soon. But it’s worth noting that all image-processing is now sandboxed to defend against the kind of vulnerabilities which were present in libheif:

> **[RCE via malformed HEIF file](https://github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335)**
>
> An upstream vulnerability in libheif (CVE-2026-32882) allows for remote code execution via Discourse image uploads.
> 
> The latest Discourse docker image includes the patched version of libheif. Upd...

---

_[View the full topic](https://meta.discourse.org/t/how-to-get-libheic/412496)._
